CVE-2020-24917: Enhancesoft Osticket
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
Affected products
- Enhancesoft Osticket: before 1.14.3 (fixed in 1.14.3)
Published 2020-08-30. Last modified 2026-07-10.